CVE-2019-15654

HIGH

Comba AC2400 Firmware - Unauthenticated Password Disclosure via upcfgAction.php

Title source: llm
STIX 2.1

Description

Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any authentication and will lead to saving the DBconfig.cfg file. At the end of the file, the login information is stored in cleartext.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.comba-telecom.com/en/news

Scores

CVSS v3 7.5
EPSS 0.0155
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
comba/ac2400_firmware
Published Mar 19, 2020
Tracked Since Feb 18, 2026